IP Library Granted Patent US 9,489,499
Granted Patent B2
US 9,489,499 · App. 14/265,923 · Granted Nov 8, 2016

Security context passing for stateless system management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,489,499
App. No.
14/265,923
Granted
Nov 8, 2016
Kind
B2
Abstract

Systems and methods for stateless system management are described. Examples include a method wherein a user sends the management system a request to act upon a managed system. The management system determines whether the user is authorized for the requested action. Upon authorization, the management system looks up an automation principal, which is a security principal native to the managed system. The management system retrieves connecting credentials for the automation principal, and connects to the managed system using the retrieved credentials. Once the managed system is connected, the management system performs the requested action on the managed system, and sends the result back to the user.

Claims (67)

1. A method comprising;

implementing, by executing instructions on a central processing unit (CPU) coupled to a memory, a centralized configuration management system for managing a plurality of diverse computer systems, each having different respective native security principals;

displaying an object graph to a user, each node of the object graph corresponding to a respective one of the diverse computer systems;

receiving a request at the centralized configuration management system, from the user, for action on a particular managed computer system, the requested action being the user's ability to browse a node in the object graph corresponding to the particular managed computer system;

authorizing the user's access to the node in the object graph based on the user's security context;

obtaining an automation principal for the particular managed computer system corresponding to the node, the automation principal being associated with the user and the particular managed computer system, wherein the automation principal is a native security principal of the particular managed computer system;

obtaining an authorization credential for the automation principal based on the user's security context;

connecting to the node using the obtained authorization credential;

browsing the node; and

displaying a result to the user.

2. The method of claim 1 further comprising:

receiving a second request from the user to browse a second node in the object graph;

obtaining an automation principal for the second node;

obtaining an authorization credential for the automation principal for the second node;

connecting to the second node using the authorization credential for the second node;

browsing the second node; and

displaying a second result to the user.

3. A method for an access control system in a heterogeneous environment created by a plurality of diverse computer systems each having different respective native security principals, the method comprising:

implementing a centralized configuration management system by executing instructions on a central processing unit (CPU) coupled to a memory, the centralized configuration management system configured to manage a plurality of diverse computer systems each having different respective native security principals;

selecting, from a central database, a particular one of the diverse computer systems;

selecting, from the central database, a role for accessing the particular one of the diverse computer systems;

detecting whether there is an automation principal associated with the role and the particular one of the diverse computer systems, wherein the automation principal is a native security principal of the particular one of the diverse computer systems;

wherein the automation principal is a native security principal of the particular one of the diverse computer systems;

selecting, from the central database, the automation principal for the particular one of the diverse computer systems;

creating an association that associates the automation principal with the role and the particular one of the diverse computer systems; and

storing the association in the database.

4. The method of claim 3 further comprising:

selecting, from a database, a user; and

creating an association that associates the automation principal with the user, the role and the particular one of the diverse computer systems.

5. The method of claim 3 further comprising creating the automation principal.

6. A networked configuration management system, the system comprising:

a configuration management station; and

a plurality of diverse managed computer systems, each having different respective native security principals, monitored by the configuration management station,

wherein the configuration management station includes:

a processing unit configured to accept a user's request to act on a particular one of the plurality of diverse managed computer systems;

an authorization unit, coupled to the processing unit, configured to authorize the user's access to the particular managed computer system based on the user's security context;

an impersonation unit, coupled to the processing unit, the impersonation unit configured to manage connections to the particular managed computer system by retrieving a current security context of the user, retrieving an automation principal and associated credential for the particular managed computer system, connect to the particular managed computer system using that credential, and execute the requested action on the particular managed computer system in the context of the associated automation principal; and

a storage device, coupled to the processing unit, for storing configuration settings of the authorization unit and the impersonation unit.

7. The system of claim 6 , wherein the authorization unit is a role based access control system.

8. The system of claim 6 , wherein the authorization unit associates a role with the particular one of the diverse managed computer systems and an automation principal for the particular one of the diverse managed computer systems.

9. The method of claim 1 , wherein obtaining an automation principal for the node includes detecting whether there is an automation principal associated with the user and the respective one of the diverse computer systems corresponding to the node, and if no automation principal is found, reporting an error to the centralized configuration management system.

10. The method of claim 1 , wherein obtaining an automation principal for the node includes:

retrieving an access control model of the respective one of the diverse computer systems corresponding to the node;

determining an automation principal for the respective one of the diverse computer systems based on its access control model; and

retrieving the automation principal for the node.

11. The method of claim 1 , wherein obtaining an automation principal for the node includes:

retrieving a security context of the user; and

selecting, from a database, an automation principal based on the security context of the user and the access control model of the respective one of the diverse computer systems.

12. The method of claim 11 , wherein the security context of the user comprises one or more roles assigned to the user.

13. The method of claim 11 , wherein the access control model of the respective one of the diverse computer systems is a role-based access control model.

14. The method of claim 11 , wherein retrieving a security context of the user includes:

retrieving an active role of the user;

determining whether there is an automation principal for the respective one of the diverse computer systems associated with the user's active role; and

signaling positive authorization if an association is found.

15. The method of claim 3 , wherein selecting an automation principal for the particular one of the diverse computer systems includes detecting whether there is an automation principal associated with the user and the particular one of the diverse computer systems, and if no automation principal is found, reporting an error.

16. The method of claim 3 , wherein obtaining an automation principal for the particular one of the diverse computer systems includes:

retrieving an access control model of the particular one of the diverse computer systems; and

determining an automation principal for the particular one of the diverse computer systems based on its access control model.

17. The method of claim 3 , wherein obtaining an automation principal for the particular one of the diverse computer systems includes:

retrieving a security context of the user; and

selecting, from a database, an automation principal based on the security context of the user and the access control model of the particular one of the diverse computer systems.

18. The method of claim 17 , wherein the security context of the user comprises one or more roles assigned to the user.

19. The method of claim 17 , wherein the access control model of the particular one of the diverse computer systems is a role-based access control model.

20. The method of claim 17 , wherein retrieving a security context of the user includes:

retrieving an active role of the user;

determining whether there is an automation principal for the particular one of the diverse computer systems associated with the user's active role; and

signaling positive authorization if an association is found.

Assignments (15)
CHANGE OF NAME Recorded Jan 10, 2025
From: BLADELOGIC, INC.
To: BMC HELIX, INC.
Reel/Frame 069870/0796 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY INTEREST Recorded Aug 10, 2017
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043514/0845 →
SECURITY INTEREST Recorded Jul 27, 2017
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043351/0231 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2016
From: KNJAZIHHIN, DENIS; REILLY, PAUL A.; BIRGER, CHET; SOLIN, DAVID; ADAMS, CARL
To: BLADELOGIC, INC.
Reel/Frame 038879/0343 →